IAP-VPN failover to other IAP

In instant IAP-VPN, we can have IPsec tunnel to main controller. If master IAP goes down and another IAP becomes master, will IPSec tunnel remains up or it will re-establish ?

If it re-establishes, is there anyway to minimize the downtime like having second IPSec tunnel from a backup IAP. So far in my research i am almost sure that there is no concept of backup IAP, but please correct me if i am wrong.